-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability centers around BackupDelete functionality which is handled by the BackupController.deleteAction method. The function processes() user-supplied filenames without adequate path traversal protection, enabling attackers to delete arbitrary files by submitting crafted paths. This aligns with the CWE-22 path traversal pattern and matches the described attack vector where authentication bypass via CSRF is possible. The Admin plugin's backup management is the logical location for this functionality in Grav CMS architecture.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| getgrav/grav | composer | >= 1.7.0-beta.1, <= 1.7.0-rc.17 | |
| getgrav/grav | composer | < 1.6.30 | 1.6.30 |
Ongoing coverage of React2Shell